Multiple security vulnerabilities have been identified in package tar, affecting version 1.0 and later. These vulnerabilities pose a moderate risk to users who rely on this package for data compression and extraction.
CVE-2026-59875 (CVSS 5.3 — Medium): node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records, allowing an attacker with normal privileges to cause a denial-of-service condition by exploiting the vulnerability.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in package tar, affecting version 1.0 and later. These vulnerabilities pose a moderate risk to users who rely on this package for data compression and extraction.
CVE-2026-59875 (CVSS 5.3 — Medium): node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records, allowing an attacker with normal privileges to cause a denial-of-service condition by exploiting the vulnerability.[emaillocker id="1283"]
CVE-2026-59874 (CVSS 4.9 — Medium): node-tar: Negative tar entry size causes infinite loop in archive replace, enabling an attacker with normal privileges to cause a denial-of-service condition by exploiting the vulnerability.
CVE-2026-59873 (CVSS 5.3 — Medium): node-tar: Decompression/parse DoS via unlimited input, allowing an attacker with normal privileges to cause a denial-of-service condition by exploiting the vulnerability.
CVE-2026-59871 (CVSS 4.9 — Medium): node-tar: Process crash via PAX numeric path type confusion, enabling an attacker with normal privileges to cause a process crash by exploiting the vulnerability. These vulnerabilities collectively present a moderate risk to users who rely on this package for data compression and extraction. Administrators should review their exposure and apply updates as necessary. These vulnerabilities collectively present a moderate risk to users who rely on this package for data compression and extraction.
These vulnerabilities collectively present a moderate risk to users who rely on this package for data compression and extraction.
We recommend you to update tar to version 7.5.17.
The following reports contain further technical details:
[/emaillocker]